Google paused its Open Source Software Vulnerability Rewards Program, known as OSS VRP, to new submissions on Oct. 1, saying "a significant rise in automated submissions, the vast majority of which are not valid" had overwhelmed the engineers and open source maintainers who review them, according to TechCrunch and Help Net Security.

The program, launched in 2022, pays security researchers for finding flaws in Google's open source projects, including Go, Angular and Protocol Buffers, Help Net Security reported.

Many of the AI generated reports described hallucinated vulnerabilities or flaws with no real world impact, requiring a person to manually read, try to reproduce and reject each one, according to both outlets.

Reports filed before Oct. 1 will still be processed, and the pause does not affect supply chain vulnerability reports or the separate Cloud VRP, Help Net Security reported. Google said it will give an update on the program in the first quarter of 2027 and pointed researchers to its Patch Rewards Program in the meantime.

A bug bounty program only works if a human reviewer can trust that a report describes a real hole in the code. When submissions are cheap to generate and expensive to verify, the maintainers without Google's engineering headcount are the ones who get buried first.